Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).

“The filename parameter is concatenated into

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Where are YC founders now? OpenAI and Anthropic, mostly

Where are YC founders now? OpenAI and Anthropic, mostly Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 15.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 102.220.160.79 — 542 requests (recent log) 89.167.35.212 — 241 requests (recent log) 216.73.216.85 — 64 requests (recent

Bonsai 27B: A 27B-Class model that runs on a phone

Bonsai 27B: A 27B-Class model that runs on a phone Source: Hacker News